An instrument version is official only when it is issued by the Hybrid Board, carries a release label and UTC timestamp, and its canonical SHA-256 fingerprint and release metadata are docketed in the Public Record. Possession of identical bytes is not issuance.
A canonical release is the official issuance of an instrument version: issued by the Hybrid Board, identified by a release label and a UTC timestamp, and recorded in the Public Record under a docket with its canonical SHA-256 fingerprint and release metadata.
Possession of a file is not issuance. Official status depends on the docket, not on the bytes, and this rule is what makes third-party copies harmless and derivatives distinguishable.
Verification is a one-minute path: obtain the canonical PDF from the release endpoint, compute SHA-256, compare with the docketed fingerprint and, where provided, verify the OpenTimestamps receipt. Authorized copies are byte-identical reproductions; publication copies may add release metadata if marked; any derivative must be marked non-authoritative and cite the fingerprint it references.
A canonical release is not an endorsement by anyone and not a claim of legal force. Two hashes can coexist for one instrument: the archival artefact's digest referenced inside a copy, and the docketed fingerprint of the public release; only the latter is verifiable against the downloadable file.